# Grok pattern match order

**URL:** <https://discuss.elastic.co/t/grok-pattern-match-order/129120>\
**Category:** Logstash\
**Created:** [April 23, 2018, 1:32pm UTC](https://discuss.elastic.co/t/grok-pattern-match-order/129120 "2018-04-23T13:32:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![KevSex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevsex/32/29031_2.png) [@KevSex](https://discuss.elastic.co/u/KevSex)\
**Post date:** [April 23, 2018, 1:32pm UTC](https://discuss.elastic.co/t/grok-pattern-match-order/129120/1 "2018-04-23T13:32:06Z")

</div>

Hi all,

I've been writing up some grok patterns to match some Cisco FirePower logs however due to the data in the logs, it sometimes matching against other patterns and making results inaccurate.

I've got the below config (data extracted for easier reading)

```
filter {

 if "firepower" in [tags] { 
  grok {
   match => [
     "message", "AccessControlRuleAction: %{DATA:aclRuleAction}, UserName: %{WORD:username}, Client: %{DATA:client}, ApplicationProtocol: %{WORD:appProtocol}, InitiatorPackets: %{NUMBER:initPackets}",
     "message", "AccessControlRuleAction: %{DATA:aclRuleAction}, InitiatorPackets: %{NUMBER:initPackets}"
     ]
  }
 }
}

```

Example log line:

```
AccessControlRuleAction: Allow, UserName: testuser, Client: SSL client, ApplicationProtocol: HTTPS, InitiatorPackets: 3

```

The problem I'm finding is that this parsing the data as follows:

```
AccessControlRuleAction: Allow, UserName: testuser, Client: SSL client, ApplicationProtocol: HTTPS,
InitiatorPackets: 3

```

Expected result:

```
AccessControlRuleAction: Allow
UserName: testuser
Client: SSL client
ApplicationProtocol: HTTPS
InitiatorPackets: 3

```

Is there any reason why the grok pattern isn't matched in order ? There are other log lines that match the 2nd pattern hence why I can't remove this.  
Is there any workarounds for something like this?

Any help would be appreciated.

Cheers,

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 23, 2018, 1:57pm UTC](https://discuss.elastic.co/t/grok-pattern-match-order/129120/2 "2018-04-23T13:57:44Z")

</div>

Using 6.2.x I am unable to reproduce this using the filter and input you gave. It matches the first pattern and breaks on match.

As a workaround you could split it into two groks and make the second one conditional on the tag \_grokparsefailure.

---

<div class="post-metadata">

**Author:** ![KevSex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevsex/32/29031_2.png) [@KevSex](https://discuss.elastic.co/u/KevSex)\
**Post date:** [April 23, 2018, 2:05pm UTC](https://discuss.elastic.co/t/grok-pattern-match-order/129120/3 "2018-04-23T14:05:04Z")

</div>

Hey,

I've managed to fix it now. Turns out the end to the full pattern wasn't correct.

Sorry to have wasted your time ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2018, 2:05pm UTC](https://discuss.elastic.co/t/grok-pattern-match-order/129120/4 "2018-05-21T14:05:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
